A week in, and it’s already doing something
Nvidia doesn’t do things halfway. Just one week after the Open Secure AI Alliance (OSAA) launched, the group has already formed a working group with a name that’s hard to forget: the Shared AI Findings Exchange, or SAFE. It’s already publishing proposals for public comment, with the Linux Foundation — itself a member — managing the process.
The group put this together while its members were gathered at Black Hat, the massive cybersecurity conference happening this week in Las Vegas. That timing wasn’t accidental. The people who care about AI security were already in one room, so why not get to work?
What the proposals actually cover
Let’s be honest: the initial proposals aren’t going to blow your mind. They’re practical, not flashy. The focus is on three things:
- How to confidentially report AI cybersecurity incidents
- How to alert the people who might be affected
- How to do blame-free analysis so everyone can learn from what happened
That last one matters more than it sounds. In cybersecurity, the instinct is often to point fingers. A blame-free approach means companies actually share what went wrong, instead of hiding it. That’s how the whole industry gets smarter.
More than just talk: actual tech contributions
The OSAA isn’t just writing documents. Members are also contributing open source tools that could eventually become a real, usable stack for securing AI agents — or defending against rogue AI attackers.
Consider what’s already on the table. Nvidia has a family of open models and an open source LLM vulnerability scanner called Garak. Okta is working on agent identity tech. Red Hat is focused on agent governance. Amazon brought both an open agent-building tool, Strands Agents, and an authorization language called Cedar. And that’s just the start.
This is the kind of concrete, technical work that makes an industry group worth paying attention to. Anyone can sign a letter. Actually contributing code is another thing entirely.
Who’s in, and who’s conspicuously absent
The membership list is impressive: Adobe, BlackRock, Cisco, Intel, Microsoft, and Visa are all in. That’s over 120 companies total.
But look closer and you’ll notice some big names missing. Anthropic, OpenAI, and Google are not members. That’s notable, because both OpenAI and Google signed the original open letter that led to this group’s creation. The letter, published last week, urged the White House to support open source AI rather than suppress it. Nvidia championed it, and over 200 tech companies signed on.
Anthropic’s absence isn’t surprising — they’ve been skeptical of open source AI for a while. But Google? They’re generally seen as a big open source supporter, and they’ve released open weight models of their own. So why aren’t they in?
It’s possible they’re waiting to see how the group evolves. It’s also possible they’re just slow to commit. Either way, it’s worth watching whether they join as the Open Secure AI Alliance builds momentum.
Moving at AI speed
The speed here is remarkable. It’s only been a couple of weeks since reports surfaced that the Trump administration might ban Chinese open weight models. That caused real consternation in the industry, which led to the open letter. And now, a week after the OSAA formed, it’s already publishing proposals.
That’s not normal for industry groups. Most take months just to agree on a mission statement. This one is already doing work.
What this means for open AI in the US
Whether or not Chinese models get banned, the fast action from this heavyweight group looks like a good thing for the U.S. open AI ecosystem. Some in the ecosystem, like the co-founder and CTO of U.S. open weight AI lab Arcee, argue that openness is the best way to counter any threat — real or imagined — from Chinese AI labs.
“Openness may be one of the most important paths to AI safety and security,” the group wrote in their letter. That’s a strong statement. The good news is they’re backing it up with action, not just words.
For anyone tracking AI security trends or open source AI developments, this is a group worth keeping an eye on. It’s young, it’s fast, and it has the backing of some of the biggest names in tech. What it does next will tell us a lot about where open AI is headed.